How to Add DMARC Records in Hetzner

📋 Hetzner DNS setup guide

This guide shows you exactly how to add DMARC records in Hetzner for your ARMD Managed DMARC Protection service. The process usually takes about 10 minutes.

You’ll use the DNS values in your ARMD.digital onboarding email, and the steps below show you where to enter them.

South African client? Hetzner South Africa became xneelo in 2019. If your hosting is with xneelo, use our xneelo guide instead. This page covers Hetzner (hetzner.com), the German cloud and hosting provider.

Not with Hetzner? Choose your DNS provider from our DMARC DNS setup guides.

🧾 Before you start

You’ll need two things:

  1. Your ARMD onboarding email containing your DNS records (record type, host name and value for each).
  2. Your Hetzner account login for the account that manages your domain’s DNS.

Don’t have the login? No problem. This is usually handled by whoever set up your website or email. Simply forward your ARMD onboarding email to your IT provider or web developer. They’ll have everything they need.

Still on the old DNS Console? Hetzner is moving DNS management into the main Hetzner Console. If your zones are still in the older standalone DNS Console (dns.hetzner.com), see the DNS Console note below — the steps differ slightly.

👥 Steps to Add DMARC Records in Hetzner

Step 1: Log in to the Hetzner Console

Go to Hetzner Accounts and log in.

Step 2: Find your domain

Open your project, then select DNS from the left menu. Select the zone matching your domain name.

Step 3: Open your records

The zone view shows all the current DNS records for your domain. Don’t change or delete anything here — you’re only adding new records.

Step 4: Add your records

Click Add record, then for each record in your ARMD onboarding email:

  1. Select the record Type from the dropdown (TXT or CNAME, as shown in your email).
  2. Copy the Host / name value from your email into the name field. Enter only the part before your domain — Hetzner adds your domain automatically. For example, enter _dmarc, not _dmarc.yourdomain.co.za.
  3. Copy the Value / destination from your email into the value field. For CNAME records, add a full stop at the end of the value (for example mail.armdprotect.com.). Without it, Hetzner appends your own domain and the record won’t work.
  4. Leave the TTL at the default.
  5. Click Add record.

Check that your new record appears in the list, then repeat for the next record.

Copy and paste — don’t retype. A single missing character will stop the record from working. Watch for your browser or email client adding spaces when copying.

Step 5: You’re done — we take it from here

There’s nothing further to submit. We check your domain automatically and will confirm by email as soon as your records are live. Hetzner usually publishes new records within minutes, though it can take a few hours, so the confirmation may not be immediate.

Once you add DMARC records in Hetzner and they go live, we handle the monitoring and protection phases of your Managed DMARC Protection service. We’ll be in touch if any of your email services need a setting switched on.

📋 Hetzner-specific notes

Still on the old DNS Console? Log in at dns.hetzner.com, select your zone, then click Add new record. The fields are the same: type, name and value, with the same two rules as above — enter only the part before your domain in the name field, and end CNAME values with a full stop. Hetzner recommends migrating zones to the main Hetzner Console; your records work either way in the meantime.

Nameservers pointing elsewhere? Your domain may be registered or hosted at Hetzner while its DNS is managed by another provider. If the zone for your domain doesn’t appear in the Console, your DNS is likely elsewhere — your ARMD onboarding email names your DNS provider, so check it matches this guide.

📚 Frequently asked questions

No. You are adding new records, not changing existing ones. Your mail flow and website continue to operate as normal while the records are added.

Hetzner usually publishes new records within minutes, though allow up to a few hours. Most records are visible almost immediately.

You don’t need to check yourself — we monitor your domain and confirm by email once the records are live.

DNS appears inside a Hetzner Console project. If you’re logged in but can’t find it, your domain’s zone may sit in a different project or under a different Hetzner account, your zones may still be in the old DNS Console (see the note above), or your DNS may be managed elsewhere. Ask whoever set up your hosting, or forward this guide to them.

What matters is where your DNS is hosted, not where your domain was registered or your website lives. If you’re not sure, we confirm this for you during onboarding — your onboarding email names your DNS provider.

For most domains, the DNS records are the main task. Once they’re live, your first DMARC reports show us which services send email on your behalf — some of these, like Microsoft 365 or newsletter platforms, may also need DKIM signing switched on in their own settings.

We’ll contact you in the first few weeks about any that need attention and tell you exactly what to do; it’s usually one setting per service.

✅ Need a hand?

If you get stuck at any step, reply to your onboarding email — it contains everything about your domain, so you’ll reach us with the full picture. If an IT provider manages your domain, forwarding them that email and this guide is usually the fastest route.

Using a different DNS provider?